Automatic SQL injection and database takeover tool
-
Updated
Sep 28, 2026 - Python
Automatic SQL injection and database takeover tool
The OWASP OFFAT tool autonomously assesses your API for prevalent vulnerabilities, though full compatibility with OAS v3 is pending. The project remains a work in progress, continuously evolving towards completion.
在线检测:veridrop.app|AI API 中转站检测工具:Claude 中转站检测、OpenAI 中转站检测、Gemini 中转站检测,中转站真伪检测、长上下文验证、思维签名验证、中转站红黑榜,自托管开源。
发现藏在前端代码里的 API,验证未授权访问风险 · 动态浏览器追踪 × JavaScript 静态分析
Burp Suite extension for API security testing with 15 attack types, 108+ payloads, intelligent fuzzing, BOLA/IDOR detection, AI integration, and automated reconnaissance. Supports REST/GraphQL/SOAP APIs with Nuclei, Turbo Intruder, and external tool integration. OWASP API Top 10 coverage.
Open-source security suite for OSINT, web scanning, API testing, SIEM integration, and AI-powered analysis
Automated API security testing
Claude Code Skills 合集:公众号文章、会议方法论提炼、多视角对话素材、文字稿润色等 8 个 Skill
Open-source security gateway for LLM APIs — prompt injection detection, PII redaction, dangerous response sanitization, and audit logging. OpenAI/Claude compatible, MCP & Agent SKILL support. Drop-in proxy for AI coding agents (Cursor, Claude Code, Codex).
Presidio security-hardened drop-in enhancements for FastAPI APIs
Pentest Coverage Tracker is a Burp Suite extension that helps penetration testers monitor testing coverage in real time. It logs discovered endpoints and tracks whether their parameters are actually tested in Burp Suite. This helps highlight untested attack surfaces and provides clear visibility of coverage for security teams.
Research Python toolkit: TikTok Android v44.x local signing (X-Gorgon, Argus, Ladon), device_register, login client, MITM helpers, tests — educational use only.
Hands-on secure code review training: learn to find vulnerabilities in Flask, Django, FastAPI through production-quality examples. Whitebox pentesting for modern web frameworks.
HowToLogin - HTLogin is authentication security scanner for login forms, APIs, and SPAs. With bypass testing, enumeration, rate-limit checks, and evidence-based detection.
6 Claude Code skills that automate the entire pentest lifecycle. From recon to exploit chains to bug bounty reports — just give it a domain. 43 scripts, zero dependencies, pure Python.
Learn backend engineering through real production failure cases.
AWS API Gateway Security Deep dive
API security rules and skills for AI coding agents: Claude Code, Cursor, GitHub Copilot, Codex, Gemini CLI, Windsurf. OWASP API Security Top 10 coverage with zero configuration.
An intelligent, machine-learning-powered API Gateway to detect and block malicious web traffic in real-time
The GenAI API Pentest Platform is a API security testing tool that leverages multiple Large Language Models (LLMs) to perform intelligent, context-aware API security assessments. Unlike traditional tools that rely on pattern matching, this platform uses AI to understand logic, predict vulnerabilities, and generate sophisticated attack scenario.
To associate your repository with the api-security topic, visit your repo's landing page and select "manage topics."